Enable 3DS2 for Checkout.com gateway integration
Learn how to enable 3D Secure 2.0 (3DS2) for Checkout.com gateway integration in Zuora to comply with PSD2 requirements using Payment Pages 2.0.
3D Secure 2.0 (3DS2) is a widely recommended solution for strong customer authentication (SCA) under PSD2. The checkout.com gateway integration in Zuora provides support for 3DS2 using Checkout.com hosted solution through Zuora's embedded iFrame of Payment Pages 2.0.
To comply with PSD2 using 3DS2, you must enable 3DS2 settings in Payment Pages. Then you can implement and use Payment Pages 2.0 as usual. See Payment Pages 2.0 Implementation Overview for more information.
Configure 3DS2 settings in Payment Pages
When setting up a Payment Page, select the Enable 3D Secure 2.0 checkbox and select the created gateway instance from the Default Payment Gateway dropdown list. You can complete other settings as usual.
Zuora recommends you to enable the CAPTCHA challenge feature so that you can limit the number of times end customers can attempt to submit the form after they fail the authentication. CAPTCHA challenge can be used with the 3DS2 feature to prevent potential bot attacks and reinforce the transaction security.
For more information about enabling and configuring CAPTCHA, see Security Measures for Payment Pages 2.0.
If you select a gateway integration that does not support 3DS2, an error message is displayed when saving the Payment Page.
Configure the gateway instance
When configuring a Checkout.com gateway instance, you can specify whether Zuora enables 3DS2 and which challenge indicator is sent to Checkout.com.
In the 3DS Challenge Indicator field on the gateway settings page, select one of the following options:
Disabled: Disables 3DS2 for the Checkout.com payment request. Use this option for one-leg-out (OLO) payments, where either you or the customer's bank is based outside the EEA or the UK.Any other challenge indicator: Enables 3DS2 and sends the selected challenge indicator to Checkout.com.
If you do not select an option, Zuora uses Disabled as the default and sends 3ds2.enabled=false to Checkout.com.
When you select an option other than Disabled, Zuora sends 3ds2.enabled=true and the selected challenge indicator to Checkout.com. The issuing bank ultimately determines whether the cardholder must complete an authentication challenge.
Select the option that matches the regulatory requirements and payment flow for your business. For more information about OLO payments and the applicable regulatory requirements, consult your payment service provider or legal advisor.
See Checkout.com Payment Gateway for more information.
The "Best practices" section in Zuora’s implementation of 3D Secure 2.0 provides best practices for reducing the possibility of failed transactions due to 3DS2 authentication errors.
Limitations
Currently, the 3D Secure 2.0 feature for checkout.com can work with only the following credit card brands:
- Visa
- Mastercard
- American Express